CVE-2026-75940
—Hard-coded credentials in Lenovo Health Android app expose health data
CVE-2026-75940 is a use of hard-coded credentials (CWE-798) in the Lenovo Health Android Application, an app distributed exclusively in the Chinese market. Because the CVSS 4.0 vector shows network attack vector with no privileges or user interaction required, the embedded credentials can be exploited remotely by an attacker without any account access or user involvement. A successful attack exposes sensitive health-related information, and the vector's high integrity impact suggests the attacker may also be able to alter stored health data. Affected users are those who have the Lenovo Health Android app installed on their devices in China. As of now there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and no exploitation has been reported.
What to do: Check whether the Lenovo Health app is installed on managed Android devices and update it to the latest version available through Chinese app stores once Lenovo publishes a fix, since no patched version number is specified in the available data. Because the app is consumer-facing and China-exclusive, enterprise defenders outside China should simply verify no users have sideloaded or installed it. Monitor Lenovo's PSIRT advisory for updated version and remediation details.
| Lenovo Health Android Application (Chinese market) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.
- Weakness
- CWE-798
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.